Executive brief
Download Monitor, a WordPress plugin used to manage and track file downloads, contains a security flaw that allows users with 'Author' level permissions to download sensitive files from the server. An attacker with these credentials could potentially access website configuration files, backup data, or other internal system files. This could lead to the exposure of database credentials and other private information, compromising the overall security of the website.
Technical details
A path traversal vulnerability (CWE-22) exists in the Download Monitor plugin for WordPress in versions up to and including 5.1.9. The flaw allows an authenticated attacker with Author-level permissions to bypass intended directory restrictions and download arbitrary files from the underlying server. The vulnerability stems from improper limitation of a pathname to a restricted directory. While the attack requires high privileges (Author role) and has high complexity, a successful exploit results in a high confidentiality impact. The issue is resolved in version 5.1.10.
Affected products
- WP Chill Download Monitor <= 5.1.9
Timeline
- 2026-02-23: other: Reported by researcher daroo
- 2026-04-20: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date